The PDF creation feature of Foxit PDF Services API supports referencing external files. Although local file access is restricted, an attacker could trigger an SSRF vulnerability by using URL redirection to bypass validation, leading to information disclosure.
References
| Link | Resource |
|---|---|
| https://www.foxit.com/support/security-bulletins.html |
Configurations
No configuration.
History
No history.
Information
Published : 2026-08-06 08:16
Updated : 2026-08-26 16:54
NVD link : CVE-2026-18597
Mitre link : CVE-2026-18597
CVE.ORG link : CVE-2026-18597
JSON object : View
Products Affected
No product.
CWE
CWE-918
Server-Side Request Forgery (SSRF)
